Class: Nexpose::APIRequest
- Inherits:
-
Object
- Object
- Nexpose::APIRequest
- Includes:
- XMLUtils
- Defined in:
- lib/nexpose/api_request.rb
Instance Attribute Summary collapse
-
#error ⇒ Object
readonly
Returns the value of attribute error.
-
#headers ⇒ Object
readonly
Returns the value of attribute headers.
-
#http ⇒ Object
readonly
Returns the value of attribute http.
-
#pause ⇒ Object
readonly
Returns the value of attribute pause.
-
#raw_response ⇒ Object
readonly
Returns the value of attribute raw_response.
-
#raw_response_data ⇒ Object
readonly
Returns the value of attribute raw_response_data.
-
#req ⇒ Object
readonly
Returns the value of attribute req.
-
#res ⇒ Object
readonly
Returns the value of attribute res.
-
#retry_count ⇒ Object
readonly
Returns the value of attribute retry_count.
-
#sid ⇒ Object
readonly
Returns the value of attribute sid.
-
#success ⇒ Object
readonly
Returns the value of attribute success.
-
#time_out ⇒ Object
readonly
Returns the value of attribute time_out.
-
#trace ⇒ Object
readonly
Returns the value of attribute trace.
-
#uri ⇒ Object
readonly
Returns the value of attribute uri.
Class Method Summary collapse
Instance Method Summary collapse
- #attributes(*args) ⇒ Object
- #execute ⇒ Object
-
#initialize(req, url, api_version = '1.1') ⇒ APIRequest
constructor
A new instance of APIRequest.
- #prepare_http_client ⇒ Object
Methods included from XMLUtils
Constructor Details
#initialize(req, url, api_version = '1.1') ⇒ APIRequest
Returns a new instance of APIRequest.
23 24 25 26 27 28 29 |
# File 'lib/nexpose/api_request.rb', line 23 def initialize(req, url, api_version='1.1') @url = url @req = req @api_version = api_version @url = @url.sub('API_VERSION', @api_version) prepare_http_client end |
Instance Attribute Details
#error ⇒ Object (readonly)
Returns the value of attribute error.
17 18 19 |
# File 'lib/nexpose/api_request.rb', line 17 def error @error end |
#headers ⇒ Object (readonly)
Returns the value of attribute headers.
7 8 9 |
# File 'lib/nexpose/api_request.rb', line 7 def headers @headers end |
#http ⇒ Object (readonly)
Returns the value of attribute http.
5 6 7 |
# File 'lib/nexpose/api_request.rb', line 5 def http @http end |
#pause ⇒ Object (readonly)
Returns the value of attribute pause.
10 11 12 |
# File 'lib/nexpose/api_request.rb', line 10 def pause @pause end |
#raw_response ⇒ Object (readonly)
Returns the value of attribute raw_response.
20 21 22 |
# File 'lib/nexpose/api_request.rb', line 20 def raw_response @raw_response end |
#raw_response_data ⇒ Object (readonly)
Returns the value of attribute raw_response_data.
21 22 23 |
# File 'lib/nexpose/api_request.rb', line 21 def raw_response_data @raw_response_data end |
#req ⇒ Object (readonly)
Returns the value of attribute req.
12 13 14 |
# File 'lib/nexpose/api_request.rb', line 12 def req @req end |
#res ⇒ Object (readonly)
Returns the value of attribute res.
13 14 15 |
# File 'lib/nexpose/api_request.rb', line 13 def res @res end |
#retry_count ⇒ Object (readonly)
Returns the value of attribute retry_count.
8 9 10 |
# File 'lib/nexpose/api_request.rb', line 8 def retry_count @retry_count end |
#sid ⇒ Object (readonly)
Returns the value of attribute sid.
14 15 16 |
# File 'lib/nexpose/api_request.rb', line 14 def sid @sid end |
#success ⇒ Object (readonly)
Returns the value of attribute success.
15 16 17 |
# File 'lib/nexpose/api_request.rb', line 15 def success @success end |
#time_out ⇒ Object (readonly)
Returns the value of attribute time_out.
9 10 11 |
# File 'lib/nexpose/api_request.rb', line 9 def time_out @time_out end |
#trace ⇒ Object (readonly)
Returns the value of attribute trace.
18 19 20 |
# File 'lib/nexpose/api_request.rb', line 18 def trace @trace end |
#uri ⇒ Object (readonly)
Returns the value of attribute uri.
6 7 8 |
# File 'lib/nexpose/api_request.rb', line 6 def uri @uri end |
Class Method Details
.execute(url, req, api_version = '1.1') ⇒ Object
123 124 125 126 127 128 129 130 |
# File 'lib/nexpose/api_request.rb', line 123 def self.execute(url, req, api_version='1.1') obj = self.new(req, url, api_version) obj.execute if (not obj.success) raise APIError.new(obj, "Action failed: #{obj.error}") end obj end |
Instance Method Details
#attributes(*args) ⇒ Object
118 119 120 121 |
# File 'lib/nexpose/api_request.rb', line 118 def attributes(*args) return if not @res.root @res.root.attributes(*args) end |
#execute ⇒ Object
49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 |
# File 'lib/nexpose/api_request.rb', line 49 def execute @conn_tries = 0 begin prepare_http_client @raw_response = @http.post(@uri.path, @req, @headers) @raw_response_data = @raw_response.read_body @res = parse_xml(@raw_response_data) if (not @res.root) @error = 'Nexpose service returned invalid XML.' return @sid end @sid = attributes['session-id'] if (attributes['success'] and attributes['success'].to_i == 1) @success = true elsif @api_version =~ /1.2/ and @res and (@res.get_elements '//Exception').count < 1 @success = true else @success = false @res.elements.each('//Failure/Exception') do |s| s.elements.each('message') do |m| @error = m.text end s.elements.each('stacktrace') do |m| @trace = m.text end end end # This is a hack to handle corner cases where a heavily loaded Nexpose instance # drops our HTTP connection before processing. We try 5 times to establish a # connection in these situations. The actual exception occurs in the Ruby # http library, which is why we use such generic error classes. rescue OpenSSL::SSL::SSLError if @conn_tries < 5 @conn_tries += 1 retry end rescue ::ArgumentError, ::NoMethodError if @conn_tries < 5 @conn_tries += 1 retry end rescue ::Timeout::Error if @conn_tries < 5 @conn_tries += 1 retry end @error = 'Nexpose host did not respond.' rescue ::Errno::EHOSTUNREACH, ::Errno::ENETDOWN, ::Errno::ENETUNREACH, ::Errno::ENETRESET, ::Errno::EHOSTDOWN, ::Errno::EACCES, ::Errno::EINVAL, ::Errno::EADDRNOTAVAIL @error = 'Nexpose host is unreachable.' # Handle console-level interrupts rescue ::Interrupt @error = 'Received a user interrupt.' rescue ::Errno::ECONNRESET, ::Errno::ECONNREFUSED, ::Errno::ENOTCONN, ::Errno::ECONNABORTED @error = 'Nexpose service is not available.' rescue ::REXML::ParseException @error = 'Nexpose has not been properly licensed.' end if !(@success or @error) @error = "Nexpose service returned an unrecognized response: #{@raw_response_data.inspect}" end @sid end |
#prepare_http_client ⇒ Object
31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 |
# File 'lib/nexpose/api_request.rb', line 31 def prepare_http_client @retry_count = 0 @retry_count_max = 10 @time_out = 30 @pause = 2 @uri = URI.parse(@url) @http = Net::HTTP.new(@uri.host, @uri.port) @http.use_ssl = true # # XXX: This is obviously a security issue, however, we handle this at the client level by forcing # a confirmation when the nexpose host is not localhost. In a perfect world, we would present # the server signature before accepting it, but this requires either a direct callback inside # of this module back to whatever UI, or opens a race condition between accept and attempt. @http.verify_mode = OpenSSL::SSL::VERIFY_NONE @headers = {'Content-Type' => 'text/xml'} @success = false end |